Skip to content
Data Science & information systems International Journal of Advances in Data and Information Systems
Open access E-ISSN 2721-3056 Acceptance rate: 28%

XGBoost Model Optimization Using PCA for Classification of Cyber Attacks on The Internet of Things

Authors

  • Afrijal Rizqi Ramadan Universitas Islam Negeri Maulana Malik Ibrahim Malang
  • Mokhamad Amin Hariyadi Universitas Islam Negeri Maulana Malik Ibrahim Malang
  • Agung Teguh Wibowo Almais Universitas Islam Negeri Maulana Malik Ibrahim Malang

DOI:

https://doi.org/10.59395/ijadis.v6i3.1465

Keywords:

Cyber Attack, Internet of Things, Smart City, XGBoost, Principal Component Analysis, SMOTE

Abstract

The rapid expansion of the Internet of Things (IoT) ecosystem has increased its susceptibility to cyberattacks, creating a critical need for reliable Intrusion Detection Systems (IDS). However, IDS performance is often hindered by severe class imbalance, high-dimensional features, and similarities among attack behaviors. This study proposes an optimized XGBoost model enhanced with the Synthetic Minority Over-sampling Technique (SMOTE) and Principal Component Analysis (PCA) to address these challenges. A systematic grid-search procedure was employed to ensure transparency, reproducibility, and optimal hyperparameter selection. The original imbalance ratio of approximately 1:27 was successfully normalized to nearly 1:1 through SMOTE. The Gotham dataset used in this study consists of roughly 350,000 IoT traffic records across eight attack categories. Five data-splitting scenarios (50:50 to 90:10) were evaluated using stratified hold-out validation supported by k-fold cross-validation. The optimized model achieved 99.68% accuracy, while extremely high AUC values approaching 1.0 were carefully validated to eliminate potential data leakage. Naive Bayes, Logistic Regression, Support Vector Machine, and Deep Neural Network were included as baseline comparisons. The results demonstrate that combining SMOTE and PCA significantly improves model stability and generalization on imbalanced IoT traffic, confirming the effectiveness of the proposed XGBSP method.

1731 538

Downloads

Download data is not yet available.

References

[1]Kronlid, C., Brantnell, A., Elf, M., Borg, J., & Palm, K. (2024). Sociotechnical analysis of factors influencing IoT adoption in healthcare: A systematic review. Technology in Society, 78, 102675. https://doi.org/https://doi.org/10.1016/j.techsoc.2024.102675 DOI: https://doi.org/10.1016/j.techsoc.2024.102675

[2]Sulton, M. S. H. W. (2025, Infrastruktur IoT Jadi Target Baru Serangan Siber 2025). CirebonKota CSIRT. Diakses dari https://csirt.cirebonkota.go.id/posts/infrastruktur-iot-jadi-target-baru-serangan-siber-2025

[3]Kikissagbe, B. R., & Adda, M. (2024). Machine Learning-Based Intrusion Detection Methods in IoT Systems: A Comprehensive review. Electronics, 13(18), 3601. https://doi.org/10.3390/electronics13183601 DOI: https://doi.org/10.3390/electronics13183601

[4]Thakkar, A., & Lohiya, R. (2021). A Review on Machine Learning and Deep Learning Perspectives of IDS for IoT: Recent Updates, Security Issues, and Challenges. Archives of Computational Methods in Engineering, 28(4), 3211–3243. https://doi.org/10.1007/s11831-020-09496-0 DOI: https://doi.org/10.1007/s11831-020-09496-0

[5]Bankó, M. B., Dyszewski, S., Králová, M., Limpek, M. B., Papaioannou, M., Choudhary, G., & Dragoni, N. (2025). Advancements in Machine Learning-Based Intrusion Detection in IoT: Research Trends and Challenges. In Algorithms (Vol. 18, Issue 4). Multidisciplinary Digital Publishing Institute (MDPI). https://doi.org/10.3390/a18040209 DOI: https://doi.org/10.3390/a18040209

[6]Imani, M., Beikmohammadi, A., & Arabnia, H. R. (2025). Comprehensive Analysis of Random Forest and XGBoost Performance with SMOTE, ADASYN, and GNUS Under Varying Imbalance Levels. Technologies, 13(3). https://doi.org/10.3390/technologies13030088 DOI: https://doi.org/10.3390/technologies13030088

[7]Balla A, Habaebi MH, Elsheikh EAA, Islam MR, Suliman FM. The Effect of Dataset Imbalance on the Performance of SCADA Intrusion Detection Systems. Sensors (Basel). 2023 Jan 9;23(2):758. doi: 10.3390/s23020758. PMID: 36679553; PMCID: PMC9865947. DOI: https://doi.org/10.3390/s23020758

[8]Doghramachi, D. F., & Ameen, S. Y. (2023). Internet of Things (IoT) Security Enhancement Using XGboost Machine Learning Techniques. Computers, Materials and Continua, 77(1), 717–732. https://doi.org/10.32604/cmc.2023.041186 DOI: https://doi.org/10.32604/cmc.2023.041186

[9]Gardner, C., & Lo, D. C.-T. (2021). PCA Embedded Random Forest. SoutheastCon 2021, 1–6. https://doi.org/10.1109/SoutheastCon45413.2021.9401949 DOI: https://doi.org/10.1109/SoutheastCon45413.2021.9401949

[10]Al-Fawa’reh, M., Al-Fayoumi, M., Nashwan, S., & Fraihat, S. (2022). Cyber threat intelligence using PCA-DNN model to detect abnormal network behavior. Egyptian Informatics Journal, 23(2), 173–185. https://doi.org/10.1016/j.eij.2021.12.001 DOI: https://doi.org/10.1016/j.eij.2021.12.001

[11]Belarbi, O., Spyridopoulos, T., Anthi, E., Rana, O., Carnelli, P., & Khan, A. (2025). Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection and Security Research [Data set]. Zenodo.

[12]Firdaus, D., Sumardi, I., & Chazar, C. (2025). Deteksi Serangan Pada Jaringan Internet Of Things Medis Menggunakan Machine Learning Dengan Algoritma XGBoost. CyberSecurity dan Forensik Digital (Vol. 8, Issue 1). DOI: https://doi.org/10.14421/csecurity.2025.8.1.5036

[13]Verma, A., & Ranga, V. (2020). Machine Learning Based Intrusion Detection Systems for IoT Applications. Wireless Personal Communications, 111(4), 2287–2310. https://doi.org/10.1007/s11277-019-06986-8 DOI: https://doi.org/10.1007/s11277-019-06986-8

[14]Javed, S. H., Ahmad, M. bin, Asif, M., Almotiri, S. H., Masood, K., & al Ghamdi, M. A. (2022). An Intelligent System to Detect Advanced Persistent Threats in Industrial Internet of Things (I-IoT). Electronics (Switzerland), 11(5). https://doi.org/10.3390/electronics11050742 DOI: https://doi.org/10.3390/electronics11050742

[15]Alqaraleh, S. (2025). An Efficient Ensemble Network Anomaly Detection System for Cyber-Attacks. Engineering, Technology and Applied Science Research, 15(4), 25549–25554. https://doi.org/10.48084/etasr.11920 DOI: https://doi.org/10.48084/etasr.11920

[16]Makwana, Dhaval & Engineer, Priti & Dabhi, Amisha & Chudasama, Hardik. (2023). Sampling Methods in Research: A Review. International Journal of Trend in Scientific Research and Development. 7. 762-768.

[17]Miller, C., Portlock, T., Nyaga, D. M., & O'Sullivan, J. M. (2024). A review of model evaluation metrics for machine learning in genetics and genomics. Frontiers in bioinformatics, 4, 1457619. https://doi.org/10.3389/fbinf.2024.1457619 DOI: https://doi.org/10.3389/fbinf.2024.1457619

[18]Muschelli, John. “ROC and AUC with a Binary Predictor: a Potentially Misleading Metric.” Journal of Classification, vol. 37, no. 3, 2020, pp. 696–708. DOI: 10.1007/s00357-019-09345-1 DOI: https://doi.org/10.1007/s00357-019-09345-1

[19]Chen, T., & Guestrin, C. (2016). Xgboost: A scalable tree boosting system. Proceedings of the 22nd Acm Sigkdd International Conference on Knowledge Discovery and Data Mining, 785–794. DOI: https://doi.org/10.1145/2939672.2939785

[20]Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419. DOI: https://doi.org/10.1016/j.jisa.2019.102419

[21]Moustafa, N. (2021). A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets. Sustainable Cities and Society, 72, 102994. DOI: https://doi.org/10.1016/j.scs.2021.102994

[22]Varotto, G., Susi, G., Tassi, L., Gozzo, F., Franceschetti, S., & Panzica, F. (2021). Comparison of resampling techniques for imbalanced datasets in machine learning: application to epileptogenic zone localization from interictal intracranial EEG recordings in patients with focal epilepsy. Frontiers in Neuroinformatics, 15, 715421. DOI: https://doi.org/10.3389/fninf.2021.715421

[23]Ring, M., Wunderlich, S., Grüdl, D., Landes, D., & Hotho, A. (2017). A toolset for intrusion and insider threat detection. In Data analytics and decision support for cybersecurity: trends, methodologies and applications (pp. 3–31). Springer. DOI: https://doi.org/10.1007/978-3-319-59439-2_1

[24]Berrar, Daniel (2019). Performance Measures for Binary Classification. In: Ranganathan, Shoba; Gribskov, Michael; Nakai, Kenta; Schönbach, Christian and Cannataro, Mario eds. Encyclopedia of Bioinformatics and Computational Biology. Reference Module in Life Sciences, 1. Elsevier, pp. 546–560. DOI: https://doi.org/10.1016/B978-0-12-809633-8.20351-8 DOI: https://doi.org/10.1016/B978-0-12-809633-8.20351-8

Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50. DOI: https://doi.org/10.1109/TETCI.2017.2772792

Downloads

Published

2025-12-30

How to Cite

[1]
A. R. Ramadan, M. A. Hariyadi, and A. T. W. Almais, “XGBoost Model Optimization Using PCA for Classification of Cyber Attacks on The Internet of Things”, International Journal of Advances in Data and Information Systems, vol. 6, no. 3, pp. 850–862, Dec. 2025, doi: 10.59395/ijadis.v6i3.1465.

Share



Plum Analytics


Similar Articles

11-20 of 122

You may also start an advanced similarity search for this article.